Source-linked AI summary
Ransomware Payments in the Bitcoin Ecosystem
Masarah Paquet-Clouston, Bernhard Haslhofer, Benoit Dupont
TL;DR
Reliable global evidence on ransomware’s direct financial impact is limited. The paper develops a data-driven method using public Bitcoin transactions and applies it to 35 ransomware families, estimating a minimum market value of USD 12,768,536 (22,967.54 BTC) from 2013 to mid-2017, with payments dominated by a few players.
Problem
Reliable global statistics on ransomware’s direct financial impact are missing.
Method
The paper identifies and traces ransomware-related Bitcoin transactions using clustering, seed addresses, and network analysis implemented on GraphSense.
Results
The 35-family market had a minimum worth of USD 12,768,536 (22,967.54 BTC) from 2013 to mid-2017 and was dominated by a few players.
Takeaways & Limitations
Law enforcement could focus limited resources on a small number of highly capable players to disrupt the ransomware market.
Takeaways & Limitations
Mixing and CoinJoin services can make illicit-activity tracing more difficult, and collectors may belong to exchanges or gambling services rather than ransomware clusters.
Abstract
from arXiv · showhide
Ransomware can prevent a user from accessing a device and its files until a ransom is paid to the attacker, most frequently in Bitcoin. With over 500 known ransomware families, it has become one of the dominant cybercrime threats for law enforcement, security professionals and the public. However, a more comprehensive, evidence-based picture on the global direct financial impact of ransomware attacks is still missing. In this paper, we present a data-driven method for identifying and gathering information on Bitcoin transactions related to illicit activity based on footprints left on the public Bitcoin blockchain. We implement this method on-top-of the GraphSense open-source platform and apply it to empirically analyze transactions related to 35 ransomware families. We estimate the lower bound direct financial impact of each ransomware family and find that, from 2013 to mid-2017, the market for ransomware payments has a minimum worth of USD 12,768,536 (22,967.54 BTC). We also find that the market is highly skewed with only a few number of players responsible for the majority of the payments. Based on these research findings, policy-makers and law enforcement agencies can use the statistics provided to understand the size of the illicit market and make informed decisions on how best to address the threat.
1 INTRODUCTION
Ransomware has become a major cybercrime concern, yet reliable global statistics on its direct financial impact remain unavailable. The paper proposes an evidence-based Bitcoin transaction method and applies it to 35 ransomware families.
- Threat and motivation: Ransomware blocks access to devices or files, typically through encryption, until victims pay attackers.Its business model monetizes victims’ valuation of locked data rather than reselling stolen information.
- Threat and motivation: 5051 ransomware families were known at the time of writing, and almost all demanded Bitcoin payments.
- Research gap: Reliable global statistics on ransomware’s impact are missing, while private-sector estimates lack disclosed methodologies and may have reporting incentives.
- Approach: Bitcoin’s public blockchain enables ransomware cash flows to be assessed when payment transactions are correctly identified.Clustering heuristics can partition Bitcoin addresses into subsets likely controlled by the same real-world actor.
- Contributions: The study applies a data-driven transaction-identification method to 35 ransomware families and implements it on GraphSense.The transaction extraction and analytics procedures are made openly available and reproducible.
- Main result: USD 12,768,536 (22,967.54 BTC) is the minimum ransomware-payment market value estimated from 2013 to mid-2017.
2 STATE OF THE ART
Prior work describes ransomware’s evolving attack techniques and Bitcoin’s traceable transaction structure, while noting important limits to attribution and tracing. This study extends existing ransomware-payment research with an automated method applied across 35 families.
- Ransomware: Ransomware monetizes illegally accessed information by charging victims to recover files, using device lockout or file encryption.
- Ransomware: Tor provides anonymous victim communication, while cryptocurrencies enable relatively anonymous payments outside established financial institutions.
- Prior assessments: The apparent speed and sophistication of ransomware evolution may overestimate the threat’s severity.
- Prior assessments: Studies of ransomware samples found that most families used superficial or flawed encryption techniques, and many attacks could be defeated.
- Bitcoin traceability: Bitcoin records confirmed transactions publicly in a transparent blockchain, with inputs and outputs identifying transferred amounts and recipient addresses.
- Bitcoin traceability: Multiple-input and change heuristics group addresses likely controlled by the same actor, supporting Bitcoin cluster construction.Change heuristics identify addresses receiving leftover funds after a payment.
- Limitations: Mixing and CoinJoin services can break or obscure links between senders and receivers, making illicit-money tracing more difficult.
- Research gap: Earlier ransomware studies focused mainly on CryptoLocker or disclosed limited methodology, whereas this study systematically traces and compares 35 families.
3 METHODOLOGY
The methodology combines Bitcoin blockchain data, address clustering, time filtering, and outgoing-relationship analysis to identify ransomware-related addresses and estimate financial flows across 35 families.
- Blockchain representations: Bitcoin address and cluster graphs represented value transfers and grouped addresses likely controlled by the same real-world actor.Address-graph edges aggregated transfers between addresses, while cluster graphs used multiple-input heuristics; public tags supported attribution to actors such as exchanges or gambling sites.
- Dataset construction: 7,118 addresses across 35 ransomware families formed the final dataset after seed collection, cluster expansion, and campaign-specific time filtering.The dataset began with collected seed addresses, was expanded through multiple-input clustering, and was filtered to reduce false positives from pre-campaign activity.
- Dataset results: Multiple-input clustering identified many ransomware-related addresses, while the seed-address distribution remained highly skewed across families.Locky and CryptoLocker address counts provided validation observations for the expansion method, and time filtering removed relatively few expanded addresses in the reported dataset.
- Outgoing relationships: Outgoing-relationships graphs traced payments from expanded ransomware addresses to receiving addresses, with directed edges encoding monetary-flow direction.For each expanded address, the method included outgoing transactions and their outputs, producing a family-specific graph of source and receiving addresses.
- Key-address identification: 2,077 key addresses were identified across the 35 studied ransomware families using incoming-relationship counts.A Bitcoin address was treated as key when its family-specific outgoing-relationships graph contained at least two unique incoming relationships.
4 THE IMPACT OF RANSOMWARE
The analysis traces ransomware payments through key addresses and estimates lower-bound financial impacts across families. It finds concentrated payments, varied transaction patterns, and important limits on interpreting traced funds as revenue.
- 4.1 Following the Money Trace: 2,077 key addresses had an average of 12 incoming relationships, a median of 6, and a maximum of 742.Key addresses were identified from outgoing-relationships graphs, with a minimum score threshold of deд(a)−≥2.
- 4.1 Following the Money Trace: Collectors aggregate payments from several payment addresses and can include addresses outside the ransomware family’s seed-address cluster.In the Locky example, one collector received 32 payments and transferred 67 BTC to another address that also functioned as a collector.
- 4.1 Following the Money Trace: Tracing found 163 key addresses linked to 28 tagged clusters, including gambling and exchange services used by some attackers.The analysis also identified 27 key addresses from five families in the Localbitcoin.com cluster and repeated interactions with SatoshiDice.
- 4.1 Following the Money Trace: Shared collectors linked Globe with Globev3 and connected TowerWeb with Cryptohitman, suggesting possible relationships among their operators or laundering routes.The latter connection involved 10 key addresses receiving money from both families, although the addresses lacked tags and had few transactions.
- 4.3 Inspecting Payments: Mean payments for 12 families ranged from very low values up to USD 2,000, while DMALockerv3, GlobeImposter, and SamSam had higher averages.DMALockerv3 requested 15 BTC in January 2016, and SamSam demanded between 1.7 BTC and 12 BTC depending on the number of infected machines.
- 4.3 Inspecting Payments: Cryptolocker, Locky, and Wannacry showed short-term viral payment patterns, whereas SamSam followed a roughly linear trend over a year.The observed period for SamSam ran from July 2016 to July 2017, consistent with its more targeted approach.
- 4.4 Market for Ransomware Payments: The first three ransomware families accounted for 86% of the market, while the other 32 families shared the remaining 12%.Locky alone accounted for more than 50% of payments in the study’s lower-bound market estimate.
- 4.4 Market for Ransomware Payments: From 2013 to mid-2017, the 35-family market had a minimum worth of USD 12,768,536 (22,967.54 BTC).The estimate sums lower-bound direct financial impacts after known collector addresses were removed to avoid double-counting.
5 DISCUSSION
The method yields family-level payment insights while deliberately estimating lower-bound direct impacts. Its conclusions show a top-heavy market, but coverage is constrained by seed addresses, attribution data, and transaction-tracing challenges.
- 5 DISCUSSION: Differentiating payment addresses from collectors enables lower-bound direct financial-impact estimates without double-counting.The method also traces payment flows to destinations such as exchanges or gambling services when contextual tags are available.
- 5 DISCUSSION: The analysis is constrained by manually collected seed addresses and multiple-input heuristics, so it can miss families and addresses outside linked clusters.The authors therefore frame their estimates as lower bounds rather than total family or market impacts.
- 5 DISCUSSION: Attribution depends on available tags; without them, clusters remain anonymous and their real-world nature cannot be inferred.The authors expect attribution data to increase as cryptocurrencies and analytics tools become more popular.
- 5 DISCUSSION: Tumblers and mixing services complicate tracing, although the method limits analysis to ransomware payment addresses and their direct outgoing neighbors.CoinJoin transactions may also be included, but matching them to other users would introduce a third-party service dependency.
- 5 DISCUSSION: Only a few ransomware players are responsible for most ransom payments, producing a top-heavy market.Masking Locky, CryptXXX, and DMALockerv3 causes a substantial drop in ransom amounts; more than half the sampled families account for less than USD 8,000 each.
- 5 DISCUSSION: The estimated market minimum is about USD 12 million, while total direct and indirect victim damages are much higher.The authors caution that the relatively modest payment total should not lead to underestimating the ransomware threat.
6 CONCLUSIONS
The paper introduces a data-driven method for tracking ransomware-related Bitcoin transactions and applies it to 35 families. It reports practical uses for threat intelligence and intervention planning, while identifying additional families, cryptocurrencies, and illicit activities as future scope.
- 6 CONCLUSIONS: The method identifies and gathers information on illicit-activity transactions through Bitcoin blockchain footprints, implemented on GraphSense and applied to 35 ransomware families.It estimates each family’s lower-bound direct financial impact and finds a highly skewed market dominated by a few players.
- 6 CONCLUSIONS: Threat-intelligence systems could use the methodology to follow ransomware payments in real time and identify explosive-growth or slowdown phases.The paper describes these inflection points as useful signals for understanding campaign payment dynamics.
- 6 CONCLUSIONS: More reliable, comprehensive, and timely information could help agencies and security companies focus interventions and awareness campaigns on the two or three most active threats.The paper connects granular longitudinal tracking with subsequent decision-making about addressing ransomware at scale.
- 6 CONCLUSIONS: Future analyses should extend coverage to additional ransomware families and account for privacy-oriented cryptocurrencies such as Monero, Ethereum, and Zcash.Kirk is identified as a ransomware family reported to use Monero for ransom payments.
- 6 CONCLUSIONS: The methodology could also be applied to other illicit activities using Bitcoin, including extortion, trafficking of illicit goods, and money laundering.